Suspicious
Suspect

406823b0c7f54417216f7d8562d837c2

PE Executable
|
MD5: 406823b0c7f54417216f7d8562d837c2
|
Size: 913.41 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very low

Hash
Hash Value
MD5
406823b0c7f54417216f7d8562d837c2
Sha1
3181195ea45b7e8ecdd7c2d7346b004220dbe72a
Sha256
ac9650718cb2712fb1a511c349fc2e5fb85092329d33c15f4d63fef310151aff
Sha384
5e7db846d980d0e932be6bb067ed4963183507fcb9fabc890783f6ad6b0488068952476f63c29dfc97a72154cdbd09a5
Sha512
4789c8a4557b0d13ca1a6a62515cbf2b947f41d76cc155c12d294e99777b78a25bbb629a5b3c511c4fb5d8bca054dbdbadf6722f4352b5a37548e1eb8ad5b3fe
SSDeep
24576:X1kn2F0efa03y3/tyOXCJy6kkk1GFCMkM1:XmCDiMOyJyln1GFCMkM
TLSH
EE1512D12E25DB05DCBE07746924CD3863B91E68B420F5E75ED93FCB36A67419A08F02

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PyramidSolitaire.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PyramidSolitaire.Properties.Resources.resources
BirdsFlyAawy
[NBF]root.Data
[NBF]root.Data-preview.png
F6
[NBF]root.Data
ImageWater
[NBF]root.Data
[NBF]root.Data-preview.png
cGwi
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: Cyhm.pdb

Module Name

Cyhm.exe

Full Name

Cyhm.exe

EntryPoint

System.Void PyramidSolitaire.Program::Main()

Scope Name

Cyhm.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Cyhm

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

260

Main Method

System.Void PyramidSolitaire.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PyramidSolitaire.AnaForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

Cyhm.exe

Full Name

Cyhm.exe

EntryPoint

System.Void PyramidSolitaire.Program::Main()

Scope Name

Cyhm.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Cyhm

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

260

Main Method

System.Void PyramidSolitaire.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void PyramidSolitaire.AnaForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

406823b0c7f54417216f7d8562d837c2 (913.41 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PyramidSolitaire.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
PyramidSolitaire.Properties.Resources.resources
BirdsFlyAawy
[NBF]root.Data
[NBF]root.Data-preview.png
F6
[NBF]root.Data
ImageWater
[NBF]root.Data
[NBF]root.Data-preview.png
cGwi
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙